Splunk® Asset and Risk Intelligence

Administer Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence is not compatible with Splunk Enterprise 9.1.2 due to known issues SPL-237796, SPL-248319 where search results in "results" have more rows than expected. Upgrade to Splunk Enterprise 9.1.3 to use Splunk Asset and Risk Intelligence.

Add and manage asset types in Splunk Asset and Risk Intelligence

Splunk Asset and Risk Intelligence includes several default asset types, but you can also add your own custom asset types or modify the default ones to better support your organization's asset discovery and investigation.

Splunk Asset and Risk Intelligence includes the following asset types by default:

  • Server
  • Workstation
  • Network
  • VOIP
  • IoT
  • Mobile
  • Uncategorized

You can't modify the Uncategorized asset type. Uncategorized assets are assets that have been discovered, but don't yet have a known asset type. Uncategorized assets can change to a different default asset type as Splunk Asset and Risk Intelligence receives more information about the asset.

Add a custom asset type

To add a custom asset type, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. In the Default configurations section, select Edit for Asset type defaults.
  3. Select Add asset type.
  4. Enter a name for your asset type. You can't use spaces, punctuation, or numbers in your asset type name.
  5. Check the Homepage check box if you want this asset type to be shown on the homepage of Splunk Asset and Risk Intelligence.
  6. Select an icon from the drop-down list for the asset type.
  7. Select Update.

Modify an asset type

To modify an asset type, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. In the Default configurations section, select Edit for Asset type defaults.
  3. Edit the asset type as needed.
  4. Select Update.

Delete an asset type

To delete an asset type, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. In the Default configurations section, select Edit for Asset type defaults.
  3. Select the x next to the asset type that you want to delete.
  4. Select Update.

Reset asset types to default

To reset the asset type to default, complete the following steps:

  1. In Splunk Asset and Risk Intelligence, select Admin and then Configuration settings.
  2. In the Default configurations section, select Edit for Asset type defaults.
  3. Select Reset to defaults.
  4. Select Update.
Last modified on 06 August, 2024
Add and manage filters in Splunk Asset and Risk Intelligence   Create and manage metrics in Splunk Asset and Risk Intelligence

This documentation applies to the following versions of Splunk® Asset and Risk Intelligence: 1.0.0, 1.0.1, 1.0.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters